NIS 2 directive

Directive (EU) 2022/2555 of the European Parliament and of the Council

of 14 December 2022

on measures for a high common level of cybersecurity across the Union,

amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)

(Text with EEA relevance)

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Having regard to the proposal from the European Commission,

After transmission of the draft legislative act to the national parliaments,

Having regard to the opinion of the European Central Bank(1)OJ C 233, 16.6.2022, p. 22.,

Having regard to the opinion of the European Economic and Social Committee(2)OJ C 286, 16.7.2021, p. 170.,

After consulting the Committee of the Regions,

Acting in accordance with the ordinary legislative procedure(3)Position of the European Parliament of 10 November 2022 (not yet published in the Official Journal) and decision of the Council of 28 November 2022.,

Whereas:

Open full page
Recital 1 The NIS 1 directive

Directive (EU) 2016/1148 of the European Parliament and the Council(4)Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union (OJ L 194, 19.7.2016, p. 1). aimed to build cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; capabilities across the Union, mitigate threats to network and information systems means: an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; used to provide essential services in key sectors and ensure the continuity of such services when facing incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555;, thus contributing to the Union’s security and to the effective functioning of its economy and society.

Recital 2 NIS 1 directive successful but had shortcomings

Since the entry into force of Directive (EU) 2016/1148, significant progress has been made in increasing the Union’s level of cyber resilience. The review of that Directive has shown that it has served as a catalyst for the institutional and regulatory approach to cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; in the Union, paving the way for a significant change in mind-set. That Directive has ensured the completion of national frameworks on the security of network and information systems means the ability of network and information systems to resist, at a given level of confidence, any event that may compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, those network and information systems; by establishing national strategies on security of network and information systems means the ability of network and information systems to resist, at a given level of confidence, any event that may compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, those network and information systems; and establishing national capabilities and by implementing regulatory measures covering essential infrastructures and entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; identified by each Member State. Directive (EU) 2016/1148 has also contributed to cooperation at Union level through the establishment of the Cooperation Group means a group as defined in Article 2, point (11), of Directive 2013/34/EU; and the network of national computer security incident means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; response teams. Notwithstanding those achievements, the review of Directive (EU) 2016/1148 has revealed inherent shortcomings that prevent it from addressing effectively current and emerging cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; challenges.

Recital 3 Cybersecurity is important

Network and information systems means: an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; have developed into a central feature of everyday life with the speedy digital transformation and interconnectedness of society, including in cross-border exchanges. That development has led to an expansion of the cyber threat means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; landscape, bringing about new challenges, which require adapted, coordinated and innovative responses in all Member States. The number, magnitude, sophistication, frequency and impact of incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; are increasing, and present a major threat to the functioning of network and information systems means: an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance;. As a result, incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; can impede the pursuit of economic activities in the internal market, generate financial loss, undermine user confidence and cause major damage to the Union’s economy and society. Cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; preparedness and effectiveness are therefore now more essential than ever to the proper functioning of the internal market. Moreover, cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; is a key enabler for many critical sectors to successfully embrace the digital transformation and to fully grasp the economic, social and sustainable benefits of digitalisation.

HAVE ADOPTED THIS DIRECTIVE:

  1. Chapter IGeneral provisions
  2. Chapter IICoordinated cybersecurity frameworks
  3. Chapter IIICooperation at union and international level
  4. Chapter IVCybersecurity risk-management measures and reporting obligations
  5. Chapter VJurisdiction and registration
  6. Chapter VIInformation sharing
  7. Chapter VIISupervision and enforcement
  8. Chapter VIIIDelegated and implementing acts
  9. Chapter IXFinal provisions
Annexes(1 – 3)
  1. Annex ISectors of high criticality
  2. Annex IIOther critical sectors
  3. Annex IIICorrelation table

Done at Strasbourg, 14 December 2022.

For the European Parliament

The President

R. METSOLA

For the Council

The President

M. BEK

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod